FRM Exam Part II · Risk Measurement and Assessment
Risk and Control Self-Assessment (RCSA) in Operational Risk
Updated 11 October 2026 · Fact-checked
RCSA is a process where each business unit identifies its own operational risks, scores them before controls (inherent risk), rates how well controls work, and derives the remaining exposure (residual risk). It uses workshops and scoring matrices. To solve questions, separate inherent, control effectiveness and residual, then act on the gaps.
Understand Risk and Control Self-Assessment (RCSA)
Risk and Control Self-Assessment (RCSA) is a qualitative tool of the operational risk framework. The people who run a business process, the first line of defense, assess the risks in that process and the controls that protect it. They know the process best, so they are well placed to spot weak points.
The logic has three layers. Inherent risk is the level of risk before any controls, based on likelihood and impact. Control effectiveness is how well the existing controls reduce that risk, looking at both design (is the control built to work?) and operation (does it actually run as intended?). Residual risk is what is left after controls. Residual risk is then compared with the firm's risk appetite. If it is too high, management must act.
The usual method is a structured workshop or questionnaire. Participants list risks by process or event type, score likelihood and impact on a scale such as 1 to 5, rate each control (for example effective, partially effective, ineffective), and read the residual rating from a matrix. Results go into a risk register with owners and action plans. The second line, operational risk management, sets the method, challenges the scores and aggregates results.
RCSA is forward-looking and builds risk awareness and ownership. But it is subjective. Scores depend on the people in the room, and they can be biased, usually towards optimism. It is therefore used with other tools: loss event data, key risk indicators, scenario analysis and audit findings. RCSA does not on its own produce a capital figure.
Key formulas to remember
- Risk rating (matrix logic)
- Risk score = Likelihood score × Impact score
- Common convention on a 1-5 scale. Firms may instead map likelihood and impact to colours on a heat map. Method is firm-specific.
- Residual risk (conceptual)
- Residual risk = Inherent risk − effect of controls
- Not a strict arithmetic rule. Many firms use a control-effectiveness matrix, or apply a percentage reduction. Always use the scheme given in the question.
- Inherent vs residual ordering
- Residual risk ≤ Inherent risk
- Controls should not raise risk. A residual score above inherent signals an error in assessment.
- Assessment components
- Inherent risk → Control assessment (design + operating effectiveness) → Residual risk → Compare with risk appetite → Action
- The sequence to remember for any RCSA question.
How to solve Risk and Control Self-Assessment (RCSA) questions
Use this order for any RCSA question, whether it asks for a definition, a calculation or a judgement.
- 1Identify the process or unit and the risk event (for example, payment error in a settlement process).
- 2Rate inherent risk by assuming no controls: assess likelihood and impact.
- 3List the key controls and judge each on design and operating effectiveness.
- 4Apply the scoring scheme given to move from inherent to residual risk. If a percentage or matrix is given, use it exactly.
- 5Compare residual risk with risk appetite or tolerance.
- 6Choose the response: accept, reduce with stronger controls, transfer (for example insurance) or avoid.
- 7Check governance: first line owns the assessment, second line challenges and aggregates, and results are combined with KRIs, loss data and scenarios.
Quickest way: Three-label shortcut
When to use it: Use when a multiple-choice question lists several statements about RCSA and you have little time.
- Label each item: inherent (before controls), control (design/operation) or residual (after controls).
- Eliminate any option that says inherent risk includes the effect of controls, or that residual exceeds inherent.
- Eliminate any option claiming RCSA gives objective, statistically precise capital numbers.
- Pick the option that has the business unit owning the assessment and the second line challenging it.
Common mistakes in Risk and Control Self-Assessment (RCSA)
Treating inherent risk as the risk after current controls.
People rate the risk they see today, which already reflects controls.
Fix: Ask: if every control failed or did not exist, how bad could this be? That is inherent.
Rating a control as effective because it exists on paper.
Design is confused with operation.
Fix: Judge both. A well-designed control that is not performed consistently is only partially effective.
Calling RCSA a quantitative, data-driven capital model.
Scores and matrices look numerical.
Fix: RCSA is mostly qualitative and subjective. Capital models rely on loss data and scenario analysis.
Assigning ownership to the operational risk department.
The central team designs the process and collects results.
Fix: The business unit (first line) owns the assessment. The second line sets the method and challenges.
Ignoring bias as a disadvantage.
Students list only benefits like ownership and awareness.
Fix: Remember the weaknesses: subjectivity, optimism bias, inconsistency between units, time cost and being a point-in-time view.
Treating a good RCSA result as proof of low risk.
Self-assessment is assumed to be reliable.
Fix: Cross-check with KRIs, incident and loss data and internal audit. Large losses in an area rated low signal a flawed assessment.
Worked examples
Example 1
A bank unit rates the inherent risk of a payment-processing error as likelihood 4 and impact 5 on 1-5 scales (score = likelihood × impact). Controls are judged to reduce the score by 60%. Risk appetite caps residual score at 10. Is residual risk within appetite?
Show the solution
- Inherent score = 4 × 5 = 20.
- Control reduction = 60% of 20 = 12.
- Residual score = 20 − 12 = 8.
- Compare: 8 ≤ 10, so it is within appetite.
- Note the result depends on the control rating being accurate, so test the controls and monitor with KRIs.
Answer: Residual score is 8, within the cap of 10.
Example 2
In an RCSA workshop, a treasury team rates a key reconciliation control as 'effective' because a written procedure exists, but logs show reconciliations were skipped on many days. The inherent risk is high. What should the second line conclude and do?
Show the solution
- The control design exists, but operating effectiveness is poor because it is not performed consistently.
- So the control should be rated partially effective or ineffective, not effective.
- Residual risk is therefore higher than the team reported, and may stay high given the high inherent risk.
- Second line should challenge the rating using evidence (logs, audit findings, loss events).
- Require an action plan with an owner and deadline, and track a KRI such as the number of missed reconciliations.
Answer: Downgrade the control rating, raise residual risk, and require remediation with monitoring. The self-assessment was optimistic.
Exam tips
- Know the three terms cold: inherent, control effectiveness, residual. Most questions test the order and what each includes.
- For advantages and disadvantages, pair them: ownership and awareness against subjectivity and bias.
- If a question gives a scoring scheme, follow it exactly even if it differs from the usual 1-5 matrix.
- Link RCSA to the other tools (KRIs, loss data, scenarios) and to three lines of defense. Many case questions ask which line does what.
- Watch for answers that treat RCSA as producing capital. It does not on its own.
Practice questions from Risk Measurement and Assessment
- A bank's LDA model aggregates capital across seven risk cells. The first approach sums the stand-alone 99.9% VaRs of the cells, assuming per…
- A bank's operational risk team uses a loss distribution approach (LDA) to estimate capital. It has only 6 years of internal loss data, and l…
- During validation of an operational risk capital model, the team finds that scenario analysis inputs from business managers cluster around r…
- A bank's RCSA for payments rates a control as 'effective' based on its design documentation. Control testing later shows it was bypassed in …
- In a loss distribution approach (LDA) model for a single operational risk category, a risk analyst assumes that annual loss frequency follow…
Risk and Control Self-Assessment (RCSA): frequently asked questions
What is the difference between inherent and residual risk in RCSA?
Inherent risk is the exposure before any controls, based on likelihood and impact. Residual risk is what remains after controls are taken into account. Residual should not exceed inherent.
What are the advantages and disadvantages of RCSA?
Advantages: it builds risk ownership and awareness, is forward-looking, captures process knowledge and gives a common language. Disadvantages: it is subjective, prone to bias and inconsistency, can be time-consuming and gives a point-in-time view that needs validation.
How is an RCSA conducted?
The business unit identifies risks by process, scores inherent likelihood and impact, rates controls, derives residual risk and compares it with appetite. This is done through workshops or questionnaires. Actions are recorded with owners, and the second line challenges and aggregates the results.
Who owns the RCSA, the first or second line?
The first line, the business unit, owns it and performs the assessment. The second line, operational risk management, defines the methodology, challenges results and reports across the firm.